Impact
GoBGP is an open source Border Gateway Protocol implementation written in Go. Prior to version 4.7.0 the software accepts a zero‑length AS_PATH during UPDATE decoding and later panics while validating that attribute for a confederation eBGP peer because it accesses the first element of the AS_PATH without bounds checking. This flaw causes a denial of service when a confederation eBGP peer receives a malformed UPDATE with an empty AS_PATH attribute, resulting in a process crash.
Affected Systems
The affected product is osrg:gobgp. All releases older than 4.7.0 are vulnerable; releases 4.7.0 and newer contain the fix.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity. The EPSS score is less than 1%, showing a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector involves a remote BGP session where an adversary injects a malformed UPDATE packet containing an empty AS_PATH attribute to a confederation eBGP peer, leading to a crash. The flaw is an unchecked array index access (CWE-125) and unchecked bounds checking (CWE-129).
OpenCVE Enrichment
Github GHSA